-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Service Binding Operator security update
Advisory ID:       RHSA-2022:5525-01
Product:           OpenShift Developer Tools and Services
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:5525
Issue date:        2022-07-07
CVE Names:         CVE-2021-3634 CVE-2021-38561 CVE-2022-1271 
====================================================================
1. Summary:

An update for service-binding-operator-bundle-container and
service-binding-operator-container is now available for OpenShift Developer
Tools and Services for OCP 4.7 +

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Security Fix(es):

* golang: out-of-bounds read in golang.org/x/text/language leads to DoS
(CVE-2021-38561)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2100495 - CVE-2021-38561 golang: out-of-bounds read in golang.org/x/text/language leads to DoS

5. JIRA issues fixed (https://issues.redhat.com/):

APPSVC-1133 - Release 1.1.1 version
APPSVC-1135 - Unable to retrieve ClusterWorkloadResourceMapping on Dev Sandbox

6. References:

https://access.redhat.com/security/cve/CVE-2021-3634
https://access.redhat.com/security/cve/CVE-2021-38561
https://access.redhat.com/security/cve/CVE-2022-1271
https://access.redhat.com/security/updates/classification/#moderate
https://docs.openshift.com/container-platform/4.14/applications/connecting_applications_to_services/odc-connecting-an-application-to-a-service-using-the-developer-perspective.html

7. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYuFkJdzjgjWX9erEAQjhEw//XlUtHhyuggxKokpYs+fX89eRq1CmRc09
4fTkFg9i3ORKsv+y/4ZIP64CO0qLJAxqNQLEKRtcmrXnE6pb8EPwP7nD0fMSRM6d
fK5oI1wQWwQnihK6UGwqD9MZ52EJQxQiEhVfsk4o0AsSFl0FWwJiuJvHjhfDT4eU
PlDmp8NAA/JwmunxWgqk4Dob2KLY3eVyMJb4Ew55NvDHhSQ+mOqKBfGAm56UV1y0
bOOnLJupw+5N7ZA9UoAvG+QJf8HzV7/4MNpK1WfzdDsxJVtowTsfgkIdB+gvRXGx
NNpAZKFAoqtm9jYdotEDV+1rPVKXIviDfu50fCPWks6dHsYpTryw7ttyuZJXIpje
bVRSXvsBAtmip9AOKl6NjyMmYpPfhQ30YmOXl+Kvdm2hTND+vTZNUpVXSiGdymTl
9/LDa1ReQGNPeGSttQG1KEgtY+f9xzhT/uCd9U3ryblJQle5BuHIeU4qryslr8AW
/13VAqcawo1yHwfXEulbTfc6EA0NRA5CrppvUtGXzarWKPi+Jxnf2oOG0c+jnDqf
N/prveS4OtCivLW2zX5Lur7e49BX5VWCXmKkkQDSJHRQjnF1Gpe3XIhkyPULSfjN
9CdqDb5eGYXzE2MkXvqXmjZHT4Q4C9iJKR7r/QXfFtKVN5PR9VKzDm7+Xi3wNuCj
BIz1LVR6q04=C2mi
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-5525:01 Moderate: Service Binding Operator security update

An update for service-binding-operator-bundle-container and service-binding-operator-container is now available for OpenShift Developer Tools and Services for OCP 4.7 + Red Hat Pro...

Summary

Security Fix(es):
* golang: out-of-bounds read in golang.org/x/text/language leads to DoS (CVE-2021-38561)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2021-3634 https://access.redhat.com/security/cve/CVE-2021-38561 https://access.redhat.com/security/cve/CVE-2022-1271 https://access.redhat.com/security/updates/classification/#moderate https://docs.openshift.com/container-platform/4.14/applications/connecting_applications_to_services/odc-connecting-an-application-to-a-service-using-the-developer-perspective.html

Package List


Severity
Advisory ID: RHSA-2022:5525-01
Product: OpenShift Developer Tools and Services
Advisory URL: https://access.redhat.com/errata/RHSA-2022:5525
Issued Date: : 2022-07-07
CVE Names: CVE-2021-3634 CVE-2021-38561 CVE-2022-1271

Topic

An update for service-binding-operator-bundle-container andservice-binding-operator-container is now available for OpenShift DeveloperTools and Services for OCP 4.7 +Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2100495 - CVE-2021-38561 golang: out-of-bounds read in golang.org/x/text/language leads to DoS

5. JIRA issues fixed (https://issues.redhat.com/):

APPSVC-1133 - Release 1.1.1 version

APPSVC-1135 - Unable to retrieve ClusterWorkloadResourceMapping on Dev Sandbox


Related News